Neurula Scribe

Privacy Policy

Effective 27 August 2026 · Neurula Technologies LLC SPC

1. Scope

This policy covers the Neurula Scribe Chrome extension and the Neurula backend services it connects to. It describes what data we process, why, where it goes, and how long it stays. It describes the system as it is built today, not as we intend it to be.

2. Who we are

Neurula Scribe is built by Neurula Technologies LLC SPC. We provide an ambient AI clinical scribe used by licensed clinicians during patient consultations. Questions and data requests: admin@neurulatechnologies.com.

3. What we collect

Account data. When your clinic creates your account we store your email address, a hashed password, your name and the facility you belong to. We use this only to authenticate you.

Microphone audio. When you press Start, your microphone is captured for the duration of the session and sent to our backend for transcription. A copy is also held, encrypted, on your own device so that a failed transcription can be retried rather than losing the consultation. See section 6.

Transcript text. The audio is converted to text, used to produce the clinical note, and held only in memory on our backend for the active session.

EMR page context.To know which field to fill, the extension reads the labels and structure of the form fields on the page (for example “Chief Complaint”). It does not transmit values already present in those fields.

Usage records. We store one record per session containing the facility, the user, the template used, output language, mode, duration, processing latency, token counts and any error code. These records contain no consultation content. We use no third-party analytics or advertising SDKs.

4. What we do not collect

  • Your browsing history outside of EMR sessions.
  • Your location.
  • Payment information.
  • Tracking cookies or advertising identifiers.

5. How we use what we collect

We process the data above for a single purpose: producing the clinical note for the visit you are currently in, and filling the corresponding EMR fields. We do not use your data for advertising or profiling, and we do not use it to train AI models.

6. Where data is stored, and for how long

On Neurula’s backend. Audio is held in memory while it is transcribed, then discarded. Transcript text and structured notes are held in memory for the active session and discarded when the session ends or after 30 minutes of inactivity. We do not write consultation content to a database. The usage records described in section 3 are stored, and contain no clinical content.

On your device — consultation audio. While a session is recording, audio is written continuously to storage inside the browser, encrypted with AES-GCM using a key issued to your user account by our backend. It is deleted as soon as transcription succeeds. If transcription fails, it is kept so you can retry, and is deleted automatically when your facility’s retention window elapses — eight hours by default, and configurable by your facility administrator between zero and 72 hours.

On your device — recent sessions. To support the “recent sessions” list in the extension, the last five structured transcripts are kept in the browser’s local storage for up to seven days. Unlike the audio described above, this transcript text is not encrypted at rest. On a shared workstation, anyone using the same Chrome profile can read it. You can remove it at any time by clearing the extension’s storage from chrome://extensions or by removing the extension.

Account data. Retained while your account is active. Deleted within 30 days of a written deletion request.

7. Who we share it with

We use three subprocessors, and only these: Deepgram, Anthropic and Amazon Web Services.

We do not authorise any subprocessor to use your data to train their models. We do not share your data with advertisers, analytics vendors, or any other third party.

8. Identifier firewall

EMR template fields tagged as patient identifiers — for example medical record number, Emirates ID, full name or date of birth — are removed on our backend before any AI call is made. They never appear in autofill output and are never sent to any subprocessor.

9. Microphone access and consent

The extension requests permission to use your microphone the first time you record. Your clinic remains responsible for obtaining patient consent for AI-assisted documentation, in line with local healthcare regulations.

10. Security

Data in transit between the extension and our backend is encrypted with TLS. Consultation audio stored on your device is encrypted with AES-GCM. Session tokens are issued by our backend, are short-lived, expire after 30 minutes of inactivity, and are not derived from any patient attribute. Passwords are stored only as bcrypt hashes. Backend access follows least-privilege principles.

11. Your rights under UAE PDPL

You may request access to your account data, correction of inaccuracies, deletion of your account, or withdrawal of consent. Email admin@neurulatechnologies.com and we will respond within 30 days.

12. Children

Neurula Scribe is a clinical tool used by licensed adult clinicians. It is not directed at children.

13. Changes to this policy

If we make material changes we will give at least 30 days’ notice by email to the address on your account before they take effect.

14. Contact

Neurula Technologies LLC SPC
admin@neurulatechnologies.com